<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: pre process binary file before injecting to splunk indexer in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/pre-process-binary-file-before-injecting-to-splunk-indexer/m-p/404348#M95631</link>
    <description>&lt;P&gt;I'd use splunk app PDI : &lt;A href="https://splunkbase.splunk.com/app/1901/"&gt;https://splunkbase.splunk.com/app/1901/&lt;/A&gt; &lt;BR /&gt;
Or the latest Splunk data stream processing : &lt;A href="https://www.splunk.com/en_us/software/stream-processing.html"&gt;https://www.splunk.com/en_us/software/stream-processing.html&lt;/A&gt; &lt;/P&gt;</description>
    <pubDate>Mon, 28 Oct 2019 10:41:04 GMT</pubDate>
    <dc:creator>sduchene_splunk</dc:creator>
    <dc:date>2019-10-28T10:41:04Z</dc:date>
    <item>
      <title>pre process binary file before injecting to splunk indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/pre-process-binary-file-before-injecting-to-splunk-indexer/m-p/404347#M95630</link>
      <description>&lt;P&gt;Hello All ,&lt;/P&gt;

&lt;P&gt;I am having a file with .dat extension populated with binary data it it . &lt;/P&gt;

&lt;P&gt;I am having a script as well which will convert binary to splunk readable format (ascii) .&lt;/P&gt;

&lt;P&gt;But i need to know is there any way , That all the data which splunk  Universal forwarder is reading from binary gets first injected to my script then it will show to splunk (In human readable format) .   I mean to say can i pre process the data before injecting to indexer &lt;/P&gt;

&lt;P&gt;Thanks in advance &lt;/P&gt;</description>
      <pubDate>Thu, 21 Feb 2019 15:35:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/pre-process-binary-file-before-injecting-to-splunk-indexer/m-p/404347#M95630</guid>
      <dc:creator>kannu</dc:creator>
      <dc:date>2019-02-21T15:35:35Z</dc:date>
    </item>
    <item>
      <title>Re: pre process binary file before injecting to splunk indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/pre-process-binary-file-before-injecting-to-splunk-indexer/m-p/404348#M95631</link>
      <description>&lt;P&gt;I'd use splunk app PDI : &lt;A href="https://splunkbase.splunk.com/app/1901/"&gt;https://splunkbase.splunk.com/app/1901/&lt;/A&gt; &lt;BR /&gt;
Or the latest Splunk data stream processing : &lt;A href="https://www.splunk.com/en_us/software/stream-processing.html"&gt;https://www.splunk.com/en_us/software/stream-processing.html&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2019 10:41:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/pre-process-binary-file-before-injecting-to-splunk-indexer/m-p/404348#M95631</guid>
      <dc:creator>sduchene_splunk</dc:creator>
      <dc:date>2019-10-28T10:41:04Z</dc:date>
    </item>
  </channel>
</rss>

